1. Parties and status
This Data Processing Agreement, or DPA, is between the business that creates the Lead Recovery Desk account as Controller and Lewis Parrish, operator of the Lead Recovery Desk service in Guernsey, Channel Islands, as Processor. Notices may be sent to info@leadrecoverydesk.com.
This DPA forms part of the Terms of Service and takes effect when the Controller accepts those terms or first submits Customer Personal Data, whichever happens first. Electronic acceptance has the same effect as signing this DPA.
The paid contracting party is Lewis Parrish. Live card payments remain disabled until paid launch is explicitly approved in configuration. If the Processor role later transfers to another entity, the Controller will receive notice and the transfer will not reduce the protections in this DPA.
2. Definitions and applicable law
Customer Personal Data means personal data processed by Lead Recovery Desk on behalf of the Controller through the service. Applicable Data Protection Law means the Data Protection (Bailiwick of Guernsey) Law, 2017 and, where applicable to the processing, UK GDPR, the Data Protection Act 2018, PECR and any replacement or binding local data protection law.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Process and Supervisory Authority have the meanings given by Applicable Data Protection Law. The schedules below form part of this DPA. If this DPA conflicts with the main Terms on processing Customer Personal Data, this DPA controls.
3. Scope, duration and roles
The subject matter, nature, purpose, data, data subjects, frequency and duration are set out in Schedule 1. The Processor acts only as a processor for Customer Personal Data. The Controller decides why contacts are processed, whether they may lawfully be contacted, what messages are approved and which sender providers are used.
The Processor is a separate controller for account administration, platform security, billing, support and its own legal obligations, as explained in the Privacy Notice. Stripe account and payment data is not Customer Personal Data under this DPA unless the parties expressly agree otherwise.
4. Documented instructions
The Processor will process Customer Personal Data only on the Controller's documented instructions, unless required by applicable law. Instructions are given through the service controls, including upload, confirm, map, clean, segment, suppress, draft, approve, schedule, send, receive configured feedback, export and delete, together with written support instructions consistent with the Terms and this DPA.
If law requires processing outside those instructions, the Processor will inform the Controller before processing unless the law prohibits notice. The Processor will promptly tell the Controller if it reasonably believes an instruction infringes Applicable Data Protection Law and may pause that instruction while the parties address the concern.
5. Controller responsibilities
The Controller will:
- provide lawful, fair and transparent instructions and maintain every required lawful basis, marketing permission, privacy notice and record;
- upload only its own prior enquirers or customers, never purchased, rented, scraped or third party lists;
- keep Customer Personal Data accurate, relevant and limited to what is needed;
- not upload restricted data prohibited by the Terms, including special category, criminal offence or children's data, without a separate written agreement and safeguards;
- approve recipients, messages, timing and sender identity and honour every objection or opt-out;
- configure access and sender providers securely and notify the Processor of any suspected breach; and
- respond to Data Subjects and regulators as Controller, using the Processor's assistance where required.
6. Confidentiality
The Processor will ensure that any person authorised to process Customer Personal Data is bound by confidentiality and receives access only where needed for the service, security, support or legal compliance. Confidentiality continues after access ends.
7. Security
Taking account of the state of the art, implementation cost, processing context and risks, the Processor will maintain appropriate technical and organisational measures. Current measures are described in Schedule 2.
The Processor may update measures where protection is not materially reduced. The Controller accepts that no internet service eliminates all risk and remains responsible for its users, devices, credentials, source data, selected providers and lawful sending decisions.
8. Subprocessors
The Controller gives general written authorisation for the subprocessors in Schedule 3. The Processor will impose data protection terms that provide substantially equivalent protection for the processing they perform and remains responsible for its obligations under this DPA.
The Processor will give at least 14 days' notice by account email before adding or replacing a subprocessor that will process Customer Personal Data, except where urgent replacement is reasonably necessary for security or service continuity. The Controller may object during that period on reasonable, documented data protection grounds. The parties will work in good faith on a reasonable solution. If none is available, the Controller may stop the affected feature or terminate before the change takes effect.
Stripe processes account and billing data but does not receive uploaded lead databases, so it is listed in the Privacy Notice rather than as a Customer Personal Data subprocessor. A customer-selected SMTP service, email provider or Twilio account is selected and contracted by the Controller. The Processor transmits to it only on the Controller's instruction and it is not appointed by the Processor as a subprocessor.
9. Data Subject requests
Considering the nature of processing, the Processor will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection and relevant automated decision rights. Self service list, suppression, export and account deletion controls are the primary assistance tools.
If the Processor receives a request clearly concerning Customer Personal Data, it will direct the requester to the Controller and notify the Controller where lawful. It will not answer on the Controller's behalf unless instructed or legally required.
10. Breaches, assessments and regulators
The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where reasonably possible, within 48 hours. Notice will include available information about the nature of the breach, affected data and people, likely consequences, measures taken or proposed and a contact for follow-up. Information may be provided in stages as it becomes available.
The Processor will take reasonable steps to contain, investigate and remediate the breach. It will assist the Controller, taking account of the processing and information available, with security obligations, breach notifications, Data Protection Impact Assessments and prior consultation with a Supervisory Authority. The Controller decides whether its regulator or Data Subjects must be notified unless law places that duty directly on the Processor.
11. Return and deletion
During the account, the Controller can export active Customer Personal Data. On a valid account deletion, expiry or termination instruction, the Processor removes the active customer database, sender connections and identifying account state, unless applicable law requires specific retention.
Pending preview imports that are not confirmed are automatically discarded after 48 hours. Fly infrastructure snapshots and compressed offsite backup objects can retain a deleted copy until normal rotation completes, for no longer than 30 days under the current configuration. Backups are isolated from ordinary use and used only for recovery and integrity purposes. If a backup is restored, the deletion instruction will be re-applied.
If provider or local cleanup cannot complete immediately, the Processor may retain a restricted pseudonymous cleanup record containing a former tenant reference, provider reference or quarantined filename, safe error class and status until the task is resolved. It does not retain the deleted lead list, login email, user ID or IP address. A minimal pseudonymous completion marker may remain where reasonably necessary to demonstrate and secure the deletion process.
12. Information and audits
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA. The Controller may request a remote audit no more than once in any 12 month period, on at least 30 days' notice, during normal business hours and without accessing another customer's data or weakening security. Additional audits are allowed where required by a Supervisory Authority or reasonably necessary after a relevant breach or credible material non-compliance.
The Controller must keep audit information confidential and use an independent auditor that is not a competitor. The Processor may charge reasonable costs for assistance beyond standard documentation unless the audit identifies material non-compliance by the Processor. The Processor will address confirmed material findings within a reasonable period.
13. International transfers
The Processor will not transfer Customer Personal Data to a country or organisation outside the permitted area under Applicable Data Protection Law without a lawful mechanism. Depending on the law and destination, this may include an adequacy decision, recognised standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another valid safeguard.
The Controller authorises transfers inherent in the subprocessors and locations described in Schedule 3, subject to those safeguards. The Processor will provide reasonable information about the applicable mechanism on request where confidentiality permits.
14. Legal requests and records
Where lawful, the Processor will notify the Controller before disclosing Customer Personal Data in response to a binding request and will disclose only what is legally required. The Processor will maintain records required of it by Applicable Data Protection Law and cooperate with a competent Supervisory Authority.
15. Liability, termination and governing law
Liability under this DPA is subject to the liability provisions in the Terms, except to the extent Applicable Data Protection Law does not permit a limitation. Termination of the Terms ends this DPA after the Processor completes the permitted return, deletion and backup rotation obligations. Clauses that must operate after termination continue for as long as necessary.
This DPA is governed by the laws of England and Wales and follows the courts clause in the Terms, without preventing a Supervisory Authority from exercising its lawful powers.
Schedule 1: Processing details
Subject matter and purpose: operating the free preview, Full Audit and Safe Send features for the Controller, including ingestion, cleaning, de-duplication, segmentation, suppression, campaign preparation, customer-approved delivery, feedback, reply intake through configured webhooks, reporting, export, support, security, backup and deletion.
Nature and operations: collection from the Controller, recording, structuring, storage, consultation, comparison, masking, alteration, retrieval, export, transmission to authorised sender providers, receipt of replies and delivery events, restriction, suppression, backup and erasure.
Duration and frequency: continuous or event-driven while the account or relevant feature is used. Unconfirmed pending imports are discarded after 48 hours. Confirmed data remains until deletion or account closure, followed by backup rotation of no more than 30 days.
Data Subjects: the Controller's prior enquirers, prospects, customers and business contacts; the Controller's authorised users where their information appears in campaign or sender records.
Personal Data: names, email addresses, phone numbers, enquiry and contact dates, source, status, quoted or estimated value, notes and permitted custom fields; campaign subjects and message bodies; recipient and scheduling data; send status and provider message identifiers; replies and outcomes; suppression and opt-out records; bounce, complaint and delivery feedback; sender domain, From and Reply-To details; encrypted customer-supplied sender credentials; and restricted pseudonymous cleanup references.
Restricted categories: no special category, criminal offence, children's, payment card, password or identity-document data is authorised under this DPA unless the parties first sign specific written instructions and safeguards.
Controller rights and obligations: those in clauses 4 and 5, including deciding purposes and lawful basis, giving instructions, informing Data Subjects, keeping data accurate and responding to rights requests.
Schedule 2: Technical and organisational measures
- Separate SQLite lead database for each customer, with authenticated tenant routing and no shared lead table.
- TLS for public application traffic; signed Secure HttpOnly SameSite Lax session cookie in production; sessions expire after no more than 30 days.
- Scrypt password hashing; reset links stored as hashes, single use and time limited.
- AES-256-GCM encryption for stored SMTP and Twilio sender credentials using a production secret held outside source code.
- Restricted provider credentials for account email and encrypted customer-selected sender credentials.
- Access controls, per-action rate limits, input validation, file-size limits and in-memory upload parsing before permitted data is written to the isolated database.
- Suppression enforcement, signed email unsubscribe links, configured STOP handling, quiet hours, daily caps, sender authentication checks, signed provider feedback and fail-closed live-sending gates.
- Audit and delivery-feedback records, stale-work recovery, database integrity checks and health monitoring.
- Fly volume snapshots and compressed offsite database backups in access-controlled S3-compatible storage, with rolling retention of no more than 30 days under the current configuration. The application does not claim an additional client-side encryption layer for backup objects.
- Self service export and deletion, provider cleanup attempts, quarantined local deletion on failure and durable restricted cleanup obligations until resolved.
- Periodic review and correction of material vulnerabilities and security incidents.
Schedule 3: Authorised subprocessors
- Fly.io: application hosting, London deployment, persistent customer database storage and infrastructure snapshots. Data: all Customer Personal Data stored or processed by the application.
- Tigris or configured S3-compatible object storage: offsite compressed database backups, which may be stored or replicated in provider-controlled regions. Data: backup copies of the customer database and related registry records.
- Resend: where configured, account email such as password resets and service notices. Resend currently sends account emails through a separate system credential. A configured system SMTP provider can be used instead for account email. Those account details are controller data covered by the Privacy Notice rather than Customer Personal Data under this DPA.
- Anthropic: optional mapping of ambiguous uploaded column headings. Data: header labels only, never contact rows. The Controller must not put personal data in headings.
Customer-selected SMTP, email and Twilio providers are not appointed by the Processor. The Controller instructs the Processor to transmit the minimum delivery data to them under the Controller's own provider relationship.